Agent-driven GitHub workflows can be manipulated through crafted public issues to unauthorisedly disclose private repositories of the enterprise when the agent has organisation-wide read access.
Seemingly secure everyday components like streaming devices and authentication flows are central attack vectors when no explicit threat modeling has taken place.
North Korean hackers systematically distribute malicious code packages across multiple major package managers and browser ecosystems to compromise developer accounts.
2.6 million Microsoft Edge users were exposed to malware in 119 hidden browser add-ons – a failure of marketplace validation processes with direct implications for enterprise-wide endpoint controls.
AI-based code agents can be manipulated through prepared GitHub repositories to execute hidden malware without common security checks detecting the risk.
Following a rail radio outage, security politicians are calling for a statutory ban on Chinese components in critical infrastructure to prevent sabotage and espionage.
GitHub blocks by default the automatic loading of code from forked pull requests in privileged workflows to prevent attackers from stealing GITHUB_TOKEN and environment variables.
CVE-2026-8461 in the FFmpeg MagicYUV decoder enables Denial-of-Service and Remote Code Execution through crafted media files in hundreds of applications; patching to version 8.1.2 is required.
Attackers are using GitHub as a malware distribution channel by mass-cloning legitimate repositories and injecting trojans, thereby compromising developer supply chains.